<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, I also changed timezone in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427860#M920622</link>
    <description>&lt;P&gt;Hi, I also changed timezone and looked through support bundle logs and everything looks ok but mapping still doesn't work.&lt;/P&gt;&lt;P&gt;Does someone have any luck with mapping?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2014 07:23:59 GMT</pubDate>
    <dc:creator>rudenko.alexander</dc:creator>
    <dc:date>2014-04-29T07:23:59Z</dc:date>
    <item>
      <title>[ISE + CDA ] IP Mappings</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427846#M920606</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;To whom who may help me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Problem Description: &lt;U&gt;Mapping IP addresses to users are not happening&lt;/U&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Scenario: Two pairs of ISE 1.2 with patch 7 and using a CDA patch 2 in order to map users that do not directly login into Active Directory. I´m using the CDA as a syslog server, receiving the syslog messages from ISE and trying to populates the mapping table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tests that i´ve conducted so far:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Reload the ISE and CDA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Changed the security levels of the syslogs&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Removed the Active Directory Servers from CDA so that I could have only one variable, the syslogs messages, to troubleshoot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Reconfigured ISE to send the syslog messages to a Solarwinds server to troubleshoot the messages ( at this point so far so good, I can see the messages sent from ISE to the external syslog server )&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Troubleshooted the ports open at CDA and ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Changed from UDP to TCP , and vice versa,&amp;nbsp; the syslog client protocol&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Followed the "Installation and Configuration Guide for Cisco Context Directory Agent, Release 1.0" doc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;but nothing that i´ve done to this point I can see the mappings from users to IP addresses. Does anyone have any clue for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´ve attached a couple of screenshoots for you to see!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427846#M920606</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2020-02-21T13:09:05Z</dc:date>
    </item>
    <item>
      <title>It sounds like you're setting</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427847#M920607</link>
      <description>&lt;P&gt;It sounds like you're setting it up correctly.&lt;/P&gt;&lt;P&gt;When you had the AD servers integrated were their authentication events mapped by CDA?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2014 15:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427847#M920607</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-04-04T15:03:46Z</dc:date>
    </item>
    <item>
      <title>Marvin, when I had the DCs</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427848#M920608</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I had the DCs configured I could see the events mapped in CDA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DS&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2014 15:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427848#M920608</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2014-04-04T15:13:41Z</dc:date>
    </item>
    <item>
      <title>Hi David,I also have same</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427849#M920609</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;I also have same problem. In CDA, i recieve syslog from ISE, but log is not include client ip address. Is it same? In log, i receive client name, device ip address (wlc) and other information.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2014 20:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427849#M920609</guid>
      <dc:creator>Tural Ahmadov</dc:creator>
      <dc:date>2014-04-04T20:17:58Z</dc:date>
    </item>
    <item>
      <title>turalahmadov, I can see the</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427850#M920610</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/turalahmadov" title="View user profile."&gt;turalahmadov,&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;I can see the messages being parsed but nothing appears in the IP-to-Identity messages!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 13:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427850#M920610</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2014-04-07T13:58:45Z</dc:date>
    </item>
    <item>
      <title>I'm running in to a similar</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427851#M920611</link>
      <description>&lt;P&gt;I'm running in to a similar issue. I've verified that both authentication passed and radius accounting packets are being received by CDA from ISE, however, nothing ever gets placed in the mappings table. Something to note: when I put logging in to debug mode it shows that the authentication passed messages are parsed, however, the accounting messages are marked as "Incomplete message received, dropped". Has anyone had any luck getting CDA to parse and map the info correctly from ISE?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 18:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427851#M920611</guid>
      <dc:creator>ggazanian</dc:creator>
      <dc:date>2014-04-11T18:42:59Z</dc:date>
    </item>
    <item>
      <title>     I´ve opened a case this</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427852#M920612</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; I´ve opened a case this morning. Let me see what Cisco says about this!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 18:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427852#M920612</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2014-04-11T18:45:47Z</dc:date>
    </item>
    <item>
      <title>Good luck!</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427853#M920613</link>
      <description>&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 20:13:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427853#M920613</guid>
      <dc:creator>ggazanian</dc:creator>
      <dc:date>2014-04-11T20:13:12Z</dc:date>
    </item>
    <item>
      <title>Hi David!I've faced the same</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427854#M920614</link>
      <description>&lt;P&gt;Hi David!&lt;/P&gt;&lt;P&gt;I've faced the same issue against IP-username mapping on CDA.&lt;/P&gt;&lt;P&gt;Have you solved it yet?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 21:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427854#M920614</guid>
      <dc:creator>rudenko.alexander</dc:creator>
      <dc:date>2014-04-16T21:39:23Z</dc:date>
    </item>
    <item>
      <title> Nothing so far. I´m waiting</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427855#M920615</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing so far. I´m waiting for TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 23:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427855#M920615</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2014-04-16T23:27:26Z</dc:date>
    </item>
    <item>
      <title>Is anyone having any luck</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427856#M920616</link>
      <description>&lt;P&gt;Is anyone having any luck with TAC or getting this running? I'm still seeing the same issues.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 19:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427856#M920616</guid>
      <dc:creator>ggazanian</dc:creator>
      <dc:date>2014-04-24T19:17:53Z</dc:date>
    </item>
    <item>
      <title>I also have the same issue</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427857#M920617</link>
      <description>&lt;P&gt;I also have the same issue and during tshooting I was pointed to Bug CSCun74460&lt;BR /&gt;https://tools.cisco.com/quickview/bug/CSCun74460&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It means that mapping could not work due to Timezone issue on ISE side. Looks like ISE sends Radius accounting with incorrect timestamp.&lt;BR /&gt;Workaround is switch to non-DayLight Savings Timezone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 13:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427857#M920617</guid>
      <dc:creator>rudenko.alexander</dc:creator>
      <dc:date>2014-04-25T13:50:49Z</dc:date>
    </item>
    <item>
      <title>Interesting... I tried</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427858#M920619</link>
      <description>&lt;P&gt;Interesting... I tried changing the timezone and it corrected the daylight savings issue in that both the CDA and ISE Syslog timestamp offset now much... but it's still not creating the mapping. Did the fix work for you?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 22:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427858#M920619</guid>
      <dc:creator>ggazanian</dc:creator>
      <dc:date>2014-04-25T22:00:51Z</dc:date>
    </item>
    <item>
      <title> Nothing so far from TAC.</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427859#M920621</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing so far from TAC. They have captured some log and screenshots and are analysing this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2014 18:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427859#M920621</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2014-04-26T18:48:55Z</dc:date>
    </item>
    <item>
      <title>Hi, I also changed timezone</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427860#M920622</link>
      <description>&lt;P&gt;Hi, I also changed timezone and looked through support bundle logs and everything looks ok but mapping still doesn't work.&lt;/P&gt;&lt;P&gt;Does someone have any luck with mapping?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 07:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427860#M920622</guid>
      <dc:creator>rudenko.alexander</dc:creator>
      <dc:date>2014-04-29T07:23:59Z</dc:date>
    </item>
    <item>
      <title>Hi David,Me to in a similar</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427861#M920623</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;Me to in a similar situation , is there any update from TAC on this.? Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 17:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427861#M920623</guid>
      <dc:creator>S Subbiah</dc:creator>
      <dc:date>2014-06-30T17:28:49Z</dc:date>
    </item>
    <item>
      <title> I´m still troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427862#M920624</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m still troubleshooting this with TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 20:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427862#M920624</guid>
      <dc:creator>David Santos</dc:creator>
      <dc:date>2014-06-30T20:42:04Z</dc:date>
    </item>
    <item>
      <title>Hi, CDA checks for the Radius</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427863#M920625</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CDA checks for the Radius passed authentication and accounting logs to create a mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1). Make sure the WLC/Switch is sending the accounting logs:&lt;/P&gt;&lt;P&gt;WLC&lt;BR /&gt;- radius-server vsa send accounting&amp;nbsp;&lt;BR /&gt;- radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;switch&lt;BR /&gt;- aaa accounting dot1x default start-stop group radius&lt;BR /&gt;- aaa accounting network default start-stop group radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2). Make sure CDA is added as a syslog and ISE is configured to send passed authentication logs to CDA (as a syslog server).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do rate if Helpful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kush&lt;/P&gt;&lt;DIV style="margin-left:1.75in;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Jul 2014 17:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427863#M920625</guid>
      <dc:creator>kushsriva</dc:creator>
      <dc:date>2014-07-16T17:24:46Z</dc:date>
    </item>
    <item>
      <title>Has this been resolved? I</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427864#M920626</link>
      <description>&lt;P&gt;Has this been resolved? I have just installed CDA with patches 1, 2, and 3 and have the same issue. I see the username and IP in the syslog parsed by CDA, but don't see it mapped in CDA. The client IP is in FRAMED-IP of the syslog.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2014 07:45:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427864#M920626</guid>
      <dc:creator>MARK BAKER</dc:creator>
      <dc:date>2014-08-20T07:45:30Z</dc:date>
    </item>
    <item>
      <title>Same here...I am waiting on</title>
      <link>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427865#M920627</link>
      <description>&lt;P&gt;Same here...&lt;/P&gt;&lt;P&gt;I am waiting on TAC to let me know if I should install patch 3 to resolve my issue. So far I am running ACS 5.5 with syslogs to CDA and there is no IP-Mappings happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2014 17:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-cda-ip-mappings/m-p/2427865#M920627</guid>
      <dc:creator>ingmiguelrosa</dc:creator>
      <dc:date>2014-08-20T17:25:16Z</dc:date>
    </item>
  </channel>
</rss>

